CVE-2026-47479
Triton Inference Server vulnerability analysis and mitigation

Overview

CVE-2026-47479 is an uncontrolled resource consumption vulnerability in NVIDIA Triton Inference Server for Linux that allows unauthenticated remote attackers to trigger denial of service. It affects all versions from 0.0 through 26.04 of the Triton Inference Server on Linux. The vulnerability was published on July 14, 2026, by NVIDIA Corporation and added to the GitHub Advisory Database the same day. It carries a CVSS v3.1 base score of 7.5 (High), assigned by NVIDIA (GitHub Advisory, Feedly).

Technical details

The vulnerability is classified as CWE-400 (Uncontrolled Resource Consumption), meaning the server fails to properly control the allocation and maintenance of limited resources when processing attacker-supplied input. The attack vector is network-based, requires no authentication, no user interaction, and low attack complexity, making it trivially automatable — a characteristic confirmed by CISA's SSVC assessment. The specific mechanism by which resource exhaustion is triggered (e.g., malformed inference requests, excessive connection handling) has not been publicly detailed in available advisories. No public proof-of-concept code has been identified (GitHub Advisory, Feedly).

Impact

Successful exploitation results in a denial of service condition, rendering the Triton Inference Server unavailable to legitimate users and applications. The impact is limited to availability — there is no confidentiality or integrity impact, meaning attackers cannot access or modify data through this vulnerability. In production AI/ML inference environments, service disruption could halt dependent workloads, pipelines, or real-time inference applications relying on the server (GitHub Advisory, Feedly).

Indicators of compromise

  • Network: Unusual spikes in inbound connections or request volume to Triton Inference Server endpoints (default ports 8000/HTTP, 8001/gRPC, 8002/metrics) from unexpected or untrusted source IPs.
  • Resource Utilization: Abnormal CPU, memory, or thread exhaustion on the host running Triton Inference Server without a corresponding increase in legitimate inference workload.
  • Logs: Triton server logs showing a high rate of requests from a single or small set of IP addresses; error messages related to resource limits or allocation failures.
  • Process: Triton server process becoming unresponsive or crashing; system-level OOM (out-of-memory) killer events targeting the Triton process.

Mitigation and workarounds

NVIDIA has released a patch addressing this vulnerability; users should upgrade NVIDIA Triton Inference Server to a version beyond 26.04 as indicated in the advisory. As an immediate workaround, implement network-level access controls (firewalls, security groups) to restrict connections to the Triton Inference Server to trusted IP ranges only, reducing the attack surface for unauthenticated network attackers. Additionally, monitor resource utilization metrics for anomalous consumption patterns and consider rate-limiting inbound requests to the server (GitHub Advisory, Feedly).

Additional resources


SourceThis report was generated using AI

Related Triton Inference Server vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-47482HIGH7.5
  • Triton Inference Server logoTriton Inference Server
  • cpe:2.3:a:nvidia:triton_inference_server
NoNoJul 14, 2026
CVE-2026-47480HIGH7.5
  • Triton Inference Server logoTriton Inference Server
  • cpe:2.3:a:nvidia:triton_inference_server
NoNoJul 14, 2026
CVE-2026-47479HIGH7.5
  • Triton Inference Server logoTriton Inference Server
  • cpe:2.3:a:nvidia:triton_inference_server
NoNoJul 14, 2026
CVE-2026-47478HIGH7.5
  • Triton Inference Server logoTriton Inference Server
  • cpe:2.3:a:nvidia:triton_inference_server
NoNoJul 14, 2026
CVE-2026-47481MEDIUM6.5
  • Triton Inference Server logoTriton Inference Server
  • cpe:2.3:a:nvidia:triton_inference_server
NoNoJul 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management